Cloudflare°ä·¢ÆäÕмÜÁ˸ߴï2 TbpsµÄDDoS¹¥»÷

°ä²¼¹¦·ò 2021-11-17

ÍøÐŰì°ä²¼¡¶ÍøÂçÊý¾Ý°²È«ÖÎÀíÌõÀý£¨Õ÷Ç󶨼û¸å£©¡·


ÍøÐŰì°ä²¼¡¶ÍøÂçÊý¾Ý°²È«ÖÎÀíÌõÀý£¨Õ÷Ç󶨼û¸å£©¡·.png


¹ú¶ÈÍøÐŰìÓÚ11ÔÂ14ÈÕ°ä²¼ÁË¡¶ÍøÂçÊý¾Ý°²È«ÖÎÀíÌõÀý£¨Õ÷Ç󶨼û¸å£©¡·µÄ¹«¿ªÕ÷Ç󶨼û֪ͨ¡£½ØÖÁ½ñÄê6Ô£¬ÎÒ¹úÍøÃñ¹æÄ£´ï10.11ÒÚ£¬Óɴ˲úÉúµÄÍøÂçÊý¾ÝÁ¿¸üÊÇÌìÎÄÊý×Ö¡£¸ÃÌõÀý¹æ·¶ÍøÂçÊý¾Ý´¦Öû£¬±£»¤Ó×ÎÒ¡¢×éÖ¯ÔÚÍøÂç¿Õ¼äµÄºÏ·¨È¨Àû£¬ÊØ»¤¹ú¶È°²È«ºÍ¹«¹²ÀûÒæ¡£Öйú»¥ÁªÍøÐ­»á·¨¹¤Î¯¸±ÃØÊ鳤ºú¸ÖÖ¸³ö£¬ÕâÊÇÐÂʱÆÚ¹æ·¶»¥ÁªÍøÆ½Ì¨ÆóÒµ£¬Ç¿»¯·´Â¢¶ÏºÍ±¾Ç®ÎÞÐòÀ©ÕŵÄÓ¦ÓÐÖ®Ò壬ҲÊÇÊØ»¤¹ú¶È°²È«¡¢±£»¤Éç»á¹«¹²ÀûÒæµÄ±ØÒª¡£


Ô­ÎÄÁ´½Ó£º

http://www.cac.gov.cn/2021-11/14/c_1638501991577898.htm


VMware½¨¸´TanzuÖеÄDoS·ì϶CVE-2021-22101


VMware½¨¸´TanzuÖеÄDoS·ì϶CVE-2021-22101.png


VMwareÔÚ11ÔÂ11ÈÕ°ä²¼²¹¶¡£¬½¨¸´ÁËTanzu Application ServiceÖеķì϶CVE-2021-22101¡£¸Ã·ì϶´æÔÚÓÚCloud FoundryµÄÔÆ½ÚÔìÆ÷(CAPI)£¬CVSSv3ÆÀ·ÖΪ7.5¡£Ô¶³Ì¹¥»÷ÕßÀûÓô˷ì϶ʱ£¬Äܹ»Í¨¹ýʹÓÃREST HTTPÒªÇóÌìÉú´óÁ¿µÄSQL²éÎʵ¼ÖÂÊý¾Ý¿â(ccdb)²»³ÉÓã¬À´´¥·¢»Ø¾ø·þÎñ״̬¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2021/11/12/vmware-releases-security-update-tanzu-application-service-vms


CISAÅû¶¶à¸öDDS¹©¸øÉ̵ÄÉ豸ÖÐ13¸ö·ì϶µÄϸ½Ú


CISAÅû¶¶à¸öDDS¹©¸øÉ̵ÄÉ豸ÖÐ13¸ö·ì϶µÄϸ½Ú.png


CISAÔÚ11ÔÂ11ÈÕ°ä²¼ÁËÒ»ÌõICSÕ÷ѯ£¬Åû¶ÁË6¸öÎÞÊý¾Ý·Ö·¢·þÎñ(DDS)¹©¸øÉ̵ÄÉ豸ÖдæÔÚµÄ13¸ö·ì϶µÄϸ½Ú¡£ÕâЩ·ìÏ¶Éæ¼°µ½Eclipse¡¢eProsimaºÍGurumNetworksµÈ¹«Ë¾£¬Éæ¼°µ½µÄÉ豸Ô̺¬CycloneDDS¡¢FastDDS¡¢GurumDDSºÍOpenDDSµÈ¡£ÆäÖнÏΪÑϳÁµÄ·ì϶ΪGurumDDSÖлùÓڶѵĻº³åÇøÒç¶Âí½Å£¨CVE-2021-38439£©£¬OCI OpenDDSÖеÄDoS·ì϶£¨CVE-2021-38447£©ºÍ¿ÉÄܵ¼Ö»ؾø·þÎñǰÌáºÍÐÅϢй¶µÄ·ì϶£¨CVE-2021-38429£©µÈ¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ics/advisories/icsa-21-315-02


Cloudflare°ä·¢ÆäÕмÜÁ˸ߴï2 TbpsµÄDDoS¹¥»÷


Cloudflare°ä·¢ÆäÕмÜÁ˸ߴï2 TbpsµÄDDoS¹¥»÷.png


ÃÀ¹úÍøÂ簲ȫ¹«Ë¾CloudflareÔÚ11ÔÂ15ÈÕ°ä·¢ÆäÕмÜÁËÆù½ñΪֹÓöµ½µÄ×î´ó¹¥»÷DDoS¹¥»÷£¬·åÖµÂÔµÍÓÚ2 Tbps¡£Õâ´Î¹¥»÷»î¶¯ÊǽáºÏÁËDNS·Å´ó¹¥»÷ºÍUDP·ººéµÄ¶àÏòÁ¿¹¥»÷£¬Õû¸ö¹ý³ÌÖ»³ÖÐøÁËÒ»·ÖÖÓ£¬À´×ÔÔ¼15000¸ö»úеÈË×é³ÉµÄ½©Ê¬ÍøÂçMirai±äÖÖ¡£Cloudflare»ã±¨³ÆµÚÈý¼¾¶ÈÍøÂç²ãDDoS¹¥»÷»î¶¯±ÈÉÏÒ»¼¾¶ÈÔö³¤ÁË44%£¬¸Ã¹«Ë¾ÔÚ8ÔÂÕмÜÁËÿÃë1720Íò´ÎÒªÇóµÄDDoS¹¥»÷£¬Î¢ÈíÔÚ10ÔÂ³ÆÆäÔÆ·þÎñAzureÕмÜÁË2.4 TbpsµÄDDoS¹¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/124634/security/cloudflare-mitigated-ddos-2-tbps.html


Ivanti°ä²¼2021ÄêQ3ÀÕË÷¹¥»÷Ì¬ÊÆµÄ·ÖÎö»ã±¨


Ivanti°ä²¼2021ÄêQ3ÀÕË÷¹¥»÷Ì¬ÊÆµÄ·ÖÎö»ã±¨.png


IvantiÓÚ11ÔÂ9ÈÕ°ä²¼ÁË2021ÄêQ3ÀÕË÷¹¥»÷Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£»ã±¨Ö¸³ö£¬µÚÈý¼¾¶Å×ëÀÕË÷Èí¼þÓйصķì϶½ÏÖ®ÉÏÒ»¼¾¶ÈÔö³¤ÁË4.5%£¬×ÜÊý´ïµ½278¸ö£»ÀÕË÷Èí¼þ¼Ò×åÔö³¤ÁË3.4%£¬×ÜÊý´ïµ½151¸ö¡£»ã±¨»¹·¢ÏÖÀÕË÷ÔËÓªÍÅ»ïÈÔÔÚ»ý¼«ÀûÓÃÁãÈÕ·ì϶£»¹¥»÷ÖÐʹÓõļ¼ÊõÒ²±äµÃÔ½À´Ô½¸´ÔÓ£¬ÀýÈçdropper as-a-service£»ÓÐ3¸ö¿É×·Òäµ½2020Äê»ò¸üÔçµÄ·ì϶ÓëÕâÒ»¼¾¶ÈµÄÐÂÀÕË÷Èí¼þÓйØ¡£


Ô­ÎÄÁ´½Ó£º

https://www.ivanti.com/lp/security/reports/2021-q3-ransomware-index-spotlight-report


Check Point°ä²¼2021Äê10ÔÂÈ«ÇòÍþвָÊý»ã±¨


Check Point°ä²¼2021Äê10ÔÂÈ«ÇòÍþвָÊý»ã±¨.png


Check PointÔÚ½üÆÚ°ä²¼ÁË2021Äê10ÔÂÈ«ÇòÍþвָÊý»ã±¨¡£»ã±¨Ö¸³ö£¬TrickbotÈÔλ¾Ó¶ñÒâÈí¼þ°ñµ¥Ö®Ê×£¬Ó°ÏìÁËÈ«Çò4%µÄ×éÖ¯£¬Æä´ÎÊÇXMRig£¨3%£©ºÍRemcos£¨2%£©£»½ÌÓýºÍ×êÑÐÐÐÒµÊÇÈ«ÇòÊܹ¥»÷×î¶àµÄÐÐÒµ£¬Æä´ÎÊÇͨѶÐÐÒµ£¬ÒÔ¼°µ±¾ÖºÍ¾üÊÂ×éÖ¯£»×î³£¼ûµÄ·ì϶ÊÇWeb·þÎñÆ÷URLĿ¼±éÀú·ì϶£¬Ô̺¬CVE-2010-4598ºÍCVE-2011-2474µÈ£»xHelper ÒÀÈ»ÊÇ×î³£¼ûµÄÒÆ¶¯¶ñÒâÈí¼þ£¬Æä´ÎÊÇAlienBotºÍXLoader¡£


Ô­ÎÄÁ´½Ó£º

https://blog.checkpoint.com/2021/11/11/october-2021s-most-wanted-malware-trickbot-takes-top-spot-for-fifth-time/